VYPR

Import And Export Users And Customers

by WordPress

CVEs (25)

  • CVE-2025-1973MedMar 22, 2025
    risk 0.25cvss 4.9epss 0.01

    The Export and Import Users and Customers plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.6.2 via the download_file() function. This makes it possible for authenticated attackers, with Administrator-level access and above, to read the…

  • CVE-2025-1972LowMar 22, 2025
    risk 0.18cvss 2.7epss 0.00

    The Export and Import Users and Customers plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the admin_log_page() function in all versions up to, and including, 2.6.2. This makes it possible for authenticated attackers, with…

  • CVE-2026-16534CriAug 3, 2026
    risk 0.00cvss 9.1epss 0.00

    The Import and export users and customers WordPress plugin before 2.4.2 does not enforce WordPress's role-assignment and per-user edit permissions during CSV import, allowing a user holding only the user-creation capability to create an administrator account and to overwrite an…

  • CVE-2025-15673MedAug 3, 2026
    risk 0.00cvss 4.9epss 0.00

    The Import and export users and customers WordPress plugin before 2.4.3 does not restrict the path of a file it reads and displays during a CSV import, allowing high-privileged users to read arbitrary files on the server.

  • CVE-2026-15026MedJul 10, 2026
    risk 0.00cvss 4.3epss 0.00

    The Import and export users and customers plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.0 via the email_template_selected. This makes it possible for authenticated attackers, with subscriber-level access and above,…

Page 2 of 2